Five-month delay in public disclosureDifferdange fraud: New timeline reveals how scammers bypassed payment checks

RTL Infos
adapted for RTL Today
A newly released timeline reveals how fraudsters controlling an architecture firm's email account defeated repeated checks by Differdange officials to divert a €400,000 payment in May, nearly five months before the municipality disclosed the scam.
Although the city admits there are lessons to be learned from the incident, officials emphasised that Differdange was the victim of an organised crime operation.
© Domingos Oliveira / RTL

The municipality of Differdange lost over €400,000 in the spring of 2026 after falling prey to a classic business email compromise scam. The fraudsters managed to intercept and take control of the email account belonging to the city's partner architecture firm, tricking municipal officials into paying a fake invoice to a criminal-controlled bank account rather than to the legitimate construction company overseeing ongoing works.

The incident was only made public months later, at the end of September, in a report by the newspaper Tageblatt.

Mayor Guy Altmeisch explained that city staff had checked the transaction multiple times before proceeding with payment, but the criminals, having access to the compromised mailbox, were able to respond convincingly to all verification requests from officials. He added that their teams verified the payment repeatedly and uncovered the fraud within two days.

The criminals had full control of their partner's email and were replying to the municipality's security checks.

Altmeisch acknowledged shortcomings in how the incident was communicated to the public, admitting that the municipal board's communication on this matter did not meet the necessary standards and the facts were disclosed too late, with some inaccuracies.

The municipal board confirmed that internal procedures were immediately strengthened following the discovery and that a criminal complaint was filed. Officials also commissioned a detailed reconstruction of events, which was reviewed and validated by the city's financial department.

The resulting timeline was made public on Friday:

  • 20 April 2026: The municipality receives an invoice of €400,000 relating to ongoing construction work, transmitted by the construction company via PEPPOL. The invoice corresponds to real services rendered.
  • 4 and 5 May: In accordance with procedure, the City's technical department asks the architecture firm to confirm that the invoice is in order. The firm confirms its validity and authorises payment. These exchanges are genuine.
  • 7 May: An email sent from the architecture firm's email system informs the municipality that the construction company wishes to know the payment date. Two employees of the company are copied in. It will later emerge that this email was written by the criminals, who had taken control of the architecture firm's email system, and that the employees' email addresses had been falsified. In the days that follow, the criminals request a change to the beneficiary's bank details using these fake construction company addresses. The City requires an official document attesting to the change, which it receives. The architecture firm, a trusted point of contact on the construction site, confirms the change. The confirmation arrives from the firm's email system, which at that point is under the criminals' control.
  • 13 May 2026: The invoice is paid to the new bank details, corresponding to a bank in the Netherlands. Paying into a foreign account is in no way unusual.
  • 19 May 2026: Two working days later, the City's revenue department detects the anomaly and identifies the fraud. That same day, the city contacts its bank and the Dutch recipient bank in an attempt to freeze the funds, and files a complaint with the Grand Ducal Police. Unfortunately, the funds had already been transferred. The city also alerts the architecture firm. Following this notification, the firm discovers that its computer systems have been compromised. This discovery enabled the firm to secure its servers.
  • 30 September 2026: The City informs the Home Affairs Ministry and makes the matter public.

In its statement to RTL Infos on Friday evening, Differdange's administration noted that, in hindsight, the board believes the relevant ministry, the town council, and citizens should have been informed sooner. The statement also clarified that the administration did fulfil its legal obligations by promptly notifying both law enforcement authorities and the relevant banks as soon as the fraud was detected.

Although the city admits there are lessons to be learned from the incident, officials emphasised that Differdange was the victim of an organised crime operation. The perpetrators exploited a legitimate service provider’s compromised email account and simultaneously impersonated both the construction company and the architecture firm using authentic communications.

Crucially, when city employees requested an official document and confirmation from the architecture office before authorising the transfer, it was the criminals themselves, controlling the email account, who responded to these requests, further misleading staff and enabling the fraud.

Back to Top
CIM LOGO